Skip to content

Update expected leaks - #52

Open
L-Jubarah-upb wants to merge 78 commits into
secure-software-engineering:masterfrom
L-Jubarah-upb:master
Open

L-Jubarah-upb wants to merge 78 commits into
secure-software-engineering:masterfrom
L-Jubarah-upb:master

Conversation

@L-Jubarah-upb

Copy link
Copy Markdown
Contributor

No description provided.

Removed expected info flows from JSON file.
Updated documentation to reflect changes in data flow and leak status.
Updated the number of leaks in the documentation and adjusted log statements to prevent leaks.
Removed expected info flows related to SMS and device ID.
Added new source and sink information for data flow.
Updated the number of leaks in the documentation and added a comment indicating the log statement as a sink.
Comment thread projects/AndroidSpecific/PrivateDataLeak2/expected-info-flows.json
Comment thread projects/InterAppCommunication/Echoer/expected-info-flows.json
@Override
public void onClick(View arg0) {
cFuncDoTheMagic(getApplicationContext());
cFuncDoTheMagic(getApplicationContext()); // source, sink

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

IMHO: The expressiveness of our specification does not allow to specify the source/sinks here accurately.
@StevenArzt Your opinion?

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

According to Steven we should put the source and sink specification into the native C code file

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The source and sink are in native code. There are tools out there that support native code analysis, so we should be precise here and remove the annotation on the Java side. Otherwise, we would put a malus on tools that are actually more precise.


try {
String string = "dIeciveDteg";
String string = "dIeciveDteg"; // source

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No, the source is:

			id = (String) method.invoke(telephonyManager);

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Note that the source in the JSON should still say android.telephony.TelephonyManager: java.lang.String getDeviceId() , since the trackers need to resolve the reflective API call.

"Line": 30
"Source": "android.telephony.TelephonyManager: java.lang.String getDeviceId()",
"Method": "com.example.onlytelephony.MainActivity: void onCreate(android.os.Bundle)",
"Line": 54

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Line 63 (the one with the reflective method invoke)

.getSystemService(Context.TELEPHONY_SERVICE);
method = c.getMethod(string, new Class<?>[0]);

id = (String) method.invoke(telephonyManager);

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

this is the source.

method = c.getMethod(reverse, new Class<?>[0]);
Toast.makeText(this, "tele manager is executed", Toast.LENGTH_SHORT)
.show();
id = (String) method.invoke(telephonyManager);

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

this is the source.

@MarcMil

MarcMil commented Sep 14, 2026

Copy link
Copy Markdown
Collaborator

Thanks for you contribution! I've added a few comments on things that should be improved.

@L-Jubarah-upb

Copy link
Copy Markdown
Contributor Author

Thanks for you contribution! I've added a few comments on things that should be improved.

Thank you for your comments! I've updated a few things but some others are still open. Can you please check my comments?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants